Security & compliance · Qatar

Edrak and the Personal Data Privacy Protection Law

The PDPPL sets the rules for handling personal data in Qatar. Edrak reads personal data only when a workflow needs it, records where it was read or written, and keeps it inside the boundary you set.

PDPPL
Law No. 13 of 2016. Personal data protection and privacy, supervised by the NCSA's data privacy function.
Applies to
Any organisation processing personal data electronically in Qatar, except where financial-centre or free-zone regimes apply instead.
Where Edrak stands
Edrak acts as a processor under your instructions. Our data handling is mapped to the PDPPL and our contract terms reflect it. Controller obligations remain yours.

What the PDPPL requires

The law and its implementing guidelines set out obligations for controllers and processors. These four are the ones an AI platform has to answer for.

  • Basis

    Lawful processing and purpose

    Personal data processed for legitimate, specified purposes, with consent where required.

  • Rights

    Individual rights

    Access, correction, erasure and objection, with timelines for response.

  • Security

    Security and breach notification

    Appropriate safeguards and notification of breaches to the regulator and affected individuals.

  • Special

    Special nature data

    Additional permission requirements for health, ethnic, religious, criminal and children's data.

How Edrak supports your PDPPL obligations

The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.

  • Purpose and minimisation

    Edrak: Each workflow declares what data it reads and why. Edrak retrieves only what the step needs and does not retain personal data beyond the workflow unless you configure it to.

    You: Defining lawful purposes and the retention your policies allow.

  • Individual rights

    Edrak: Records show where personal data was read or written, so access, correction and deletion requests can be traced through every workflow.

    You: Receiving and fulfilling requests within statutory timelines.

  • Cross-border transfers

    Edrak: Deployment options keep data in-country. Model routing lets you stop personal data leaving your boundary while still using hosted models for other work.

    You: Assessing transfer conditions and approving any exceptions.

  • Processor terms

    Edrak: Contract terms set out Edrak's role, sub-processors, security measures and breach notification, in the form your regulator expects.

    You: Registering processing activities and appointing a privacy officer where required.

  • Records

    Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.

    You: Retention periods and breach-notification timelines.

  • Identity and access

    Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.

    You: Identities, roles, and joiner, mover and leaver processes.

For your security and compliance teams

We share a requirement-by-requirement mapping to the PDPPL frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.

Talk to our team

The PDPPL issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Confirm applicability with your compliance team.